Calico
Tigera · 8 CVEs
Unauthenticated Go pprof exposure in Calico debug server
Jul 30, 2026
Calico Tier Authorization Bypass via DeleteCollection
Jul 30, 2026
L7 policy bypass via unnormalized HTTP path matching
Jul 30, 2026
ServiceAccount token disclosure via Azure IPAM CNI plugin logs
May 28, 2026
Calicoctl leaks cluster credentials to stderr when verbose logging is enabled
May 28, 2026
ServiceAccount token disclosure via install-cni container logs
May 28, 2026
Privilege escalation in Calico CNI install binary
Apr 29, 2024
Calico Typha hangs during unclean TLS handshake
Nov 6, 2023
Calico and Calico Enterprise may be vulnerable to route hijacking with the floating IP feature
Jun 6, 2022
Calico nodes IPv6 traffic redirection from route advertisment
Jun 3, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-41186 | Unauthenticated Go pprof exposure in Calico debug server | MEDIUM | 0.67% | Jul 30, 2026 |
| CVE-2026-41187 | Calico Tier Authorization Bypass via DeleteCollection | MEDIUM | 0.39% | Jul 30, 2026 |
| CVE-2026-6540 | L7 policy bypass via unnormalized HTTP path matching | HIGH | 0.54% | Jul 30, 2026 |
| CVE-2026-41185 | ServiceAccount token disclosure via Azure IPAM CNI plugin logs | MEDIUM | 0.34% | May 28, 2026 |
| CVE-2026-6720 | Calicoctl leaks cluster credentials to stderr when verbose logging is enabled | HIGH | 0.30% | May 28, 2026 |
| CVE-2026-41184 | ServiceAccount token disclosure via install-cni container logs | MEDIUM | 0.53% | May 28, 2026 |
| CVE-2024-33522 | Privilege escalation in Calico CNI install binary | HIGH | 0.22% | Apr 29, 2024 |
| CVE-2023-41378 | Calico Typha hangs during unclean TLS handshake | HIGH | 0.72% | Nov 6, 2023 |
| CVE-2022-28224 | Calico and Calico Enterprise may be vulnerable to route hijacking with the floating IP feature | MEDIUM | 0.61% | Jun 6, 2022 |
| CVE-2020-13597 | Calico nodes IPv6 traffic redirection from route advertisment | MEDIUM | 0.90% | Jun 3, 2020 |
Showing 1 to 8 of 8 CVEs